Analytics
Informational
✕
Remote account enumeration
Multiple non-existing accounts failed to remotely log in to a host in a short period of time. This may indicate an attacker is trying to remotely enumerate accounts.
- Module:
- Identity Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Discovery (TA0007) Credential Access (TA0006)
ATT&CK techniques: Account Discovery (T1087) Brute Force (T1110)
Attacker's goals:
Discover valid accounts to gain credentials.
Investigative actions:
Check if the login attempts were part of a legitimate misunderstanding of the system or part of an attack.
- Test period:
- 10 Minutes
- Deduplication:
- 1 Day
2 variations:
- Suspicious Remote domain account enumeration Medium (parent: Informational)
- Remote account enumeration on domain accounts Low (parent: Informational)